Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

Trust policies

A TrustPolicy grants a set of subjects the right to exchange their identity for a provider credential on one Connection, never wider than…

This method is not served on the public API. api.sylphx.com does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

A TrustPolicy grants a set of subjects the right to exchange their identity for a provider credential on one Connection, never wider than the policy's permissions and repositories.

Service Sylphx Broker · Resource type broker.sylphx.com/TrustPolicy · Name pattern orgs/{org}/trust_policies/{trust_policy} · Shape spec_status

Not available yet. Sylphx Broker is declared in the registry but no backend serves it: every call answers 501 with the problem code UNIMPLEMENTED.

#Fields

FieldTypeWhat it is
namestringorgs/{org}/trust_policies/{trust_policy}.
uidstringtrp_<cell><ulid>. Output only.
metaResourceMetaResource metadata.
specTrustPolicySpecDesired state. Required.
statusTrustPolicyStatusObserved state. Output only.

#Methods

Every method of the collection, in the registry's order, with the scope it needs. The full request, response and examples are one link away.

MethodCallWhat it does
GETgetGets a trust policy.
GETlistLists an org's trust policies.
POSTcreateCreates a trust policy.
PATCHupdateUpdates a trust policy.
DELETEdeleteDeletes a trust policy.
POSTexchange_tokenExchanges the caller's workload identity for a short-lived provider credential under a trust policy (RFC 8693 token exchange). The credential is narrowed to the request and cached per installation and permission set; a permission the Connection lacks is PERMISSION_DENIED with reason CapabilityMissing, never an outage.

#get

Gets a trust policy.

GET https://api.sylphx.com/v1/orgs/acme/trust_policies/trust-policy · scope broker:read · effect read · not available yet · Request, response and examples

#list

Lists an org's trust policies.

GET https://api.sylphx.com/v1/orgs/acme/trust_policies · scope broker:read · effect read · not available yet · paginated · Request, response and examples

#create

Creates a trust policy.

POST https://api.sylphx.com/v1/orgs/acme/trust_policies · scope broker:admin · effect write · not available yet · Request, response and examples

#update

Updates a trust policy.

PATCH https://api.sylphx.com/v1/orgs/acme/trust_policies/trust-policy · scope broker:admin · effect write · not available yet · Request, response and examples

#delete

Deletes a trust policy.

DELETE https://api.sylphx.com/v1/orgs/acme/trust_policies/trust-policy · scope broker:admin · effect destructive · not available yet · Request, response and examples

#exchange_token

Exchanges the caller's workload identity for a short-lived provider credential under a trust policy (RFC 8693 token exchange). The credential is narrowed to the request and cached per installation and permission set; a permission the Connection lacks is PERMISSION_DENIED with reason CapabilityMissing, never an outage.

POST https://api.sylphx.com/v1/orgs/acme/trust_policies/trust-policy:exchangeToken · scope broker:exchange · effect write · not available yet · Request, response and examples